Iranian-Linked Cyber Attack Disrupted British Power Plant for Four Days
The breach of a small gas-fired peaker plant in July represents the first known foreign state shutdown of a UK power facility, amid rising AI-driven threats to critical utilities.

A cyber intrusion brought a small British electricity generation facility to a complete standstill for four days during July, marking what security analysts view as the first time Iranian-linked threat actors have successfully disrupted a UK power site. The incident, first reported by The Next Web following initial coverage by The Telegraph, affected a localized gas-fired facility used to compensate for fluctuations in national energy supply. While the breach caused no widespread power outages or grid instability, it underscores mounting vulnerabilities within distributed critical infrastructure assets as state-backed threat groups refine their offensive capabilities.
The affected facility operates as a peaker plant, one of dozens of small gas-powered generators situated across Britain that run intermittently when renewable output drops or demand spikes. According to British government officials, the generator’s capacity sits well below statutory threshold limits that mandate formal incident reporting, with one government source characterizing its output as negligible relative to overall grid capacity. A spokesperson for the British government confirmed the incident to media outlets, stating that at no point was there any broader risk to the energy network. Following the intrusion, UK Energy Minister Michael Shanks acknowledged on social media that his department convened briefings with energy sector chief executives to issue defensive guidance, though official agencies have refrained from formally naming the facility or publicly attributing the attack to Tehran.
The UK power plant outage coincided with a widespread wave of cyber attacks directed at American municipal water systems. Beginning in late July in Minnesota, intrusions expanded to affect wastewater and drinking water utilities across at least 12 states, including Michigan, Georgia, South Dakota, and New Jersey. U.S. federal authorities—including the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Environmental Protection Agency (EPA)—attributed the American utility breaches to Iranian state-linked hackers. In several locations, the compromises resulted in tap pressure drops, physical equipment disruptions, localized flooding, and mandatory boil-water notices for municipal customers.
A central factor in these parallel campaigns involves the exploitation of industrial control hardware using increasingly sophisticated techniques. Federal agencies in the U.S. issued joint warnings highlighting that attackers are deploying AI-generated exploitation scripts to gain unauthorized access to internet-connected programmable logic controllers (PLCs), specifically targeting Siemens S7 units deployed across energy, water, and manufacturing installations. Security analysts, including former FBI cyber analyst Cynthia Kaiser, noted that these methods represent a continuation of suspected Iranian operations against industrial equipment. A recent UK Cabinet Office risk assessment similarly warned that artificial intelligence is lowering barriers to entry by automating attack deployment, rating the likelihood of a successful critical infrastructure breach in Britain at between 5% and 25%.
The breach highlights a shifting cyber threat landscape as Tehran expands its offensive operations across Western nations. According to findings by the UK Intelligence and Security Committee, Iran spends tens of millions of dollars annually funding hacking organizations comprising hundreds of personnel. While parliamentary reports previously deemed a successful attack on British domestic infrastructure unlikely, intelligence agencies indicate that state-sponsored cyber strikes have surged across Europe and North America over the past year. Nations including Germany, Poland, Finland, Belgium, and Albania have recorded suspected Iranian cyber activity, while the U.S. Department of Justice recently charged 17 Iranian nationals in connection with extensive cyber theft campaigns linked to the Islamic Revolutionary Guard Corps.
The incident underscores the operational pressures confronting national cyber defense organizations as state actors target lesser-defended operational technology. Richard Horne, chief executive of the UK National Cyber Security Centre (NCSC)—an agency operating under GCHQ—disclosed earlier this year that the organization managed more than 200 incidents targeting critical national infrastructure over the preceding 12 months. Horne cautioned that the agency now routinely handles at least four nationally significant cyber attacks every week, warning that escalation in global conflicts could further drive up attack frequency against domestic assets.
In response to the evolving threat profile of distributed generation sites and AI-enabled exploit vectors, British authorities are reviewing statutory frameworks. The UK Department for Energy Security and Net Zero confirmed that it is actively updating its cybersecurity regulations to address gaps exposed by smaller, lower-threshold utility operators. Furthermore, the UK government plans to publish a broader national energy resilience strategy later this year aimed at establishing stricter security standards across all components of the energy grid.
Sources
Written by
The Company Wire
Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.



